{"id":795,"date":"2013-02-28T15:57:47","date_gmt":"2013-02-28T23:57:47","guid":{"rendered":"http:\/\/e-olio.com\/cknow\/cms\/?p=795"},"modified":"2013-04-16T13:23:56","modified_gmt":"2013-04-16T20:23:56","slug":"companion-files","status":"publish","type":"post","link":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html","title":{"rendered":"Companion Files"},"content":{"rendered":"<p><div class=\"simplePullQuote right\"><p><strong>Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.<\/strong><\/p>\n<\/div>Would you believe that a virus can infect your files without changing a single byte in the infected file? Well, it&#8217;s true; two different ways in fact! The more common of the two ways is called the companion or spawning virus (the other is a <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/directories-cluster-viruses.html\">cluster virus<\/a>). The companion virus infects your files by locating all files with names ending in EXE. The virus then creates a matching file name ending in COM that contains the viral code.<\/p>\n<p>Here&#8217;s what happens: Let&#8217;s say a companion virus is executing on your PC and decides it&#8217;s time to infect a file. It looks around and happens to find a file called PGM.EXE. It now creates a file called PGM.COM containing the virus. The virus usually plants this file in the same directory as the .EXE file but it could place it in any directory on your DOS path. If you type PGM and hit enter, DOS will execute PGM.COM instead of PGM.EXE. (In order, DOS will execute COM, then EXE, then BAT files of the same root name, if they are all in the same directory.) The virus executes, possibly infecting more files and then loads and executes PGM.EXE. The user probably won&#8217;t notice anything wrong.<\/p>\n<p>This type of virus is fairly easy to detect by the presence of the extra COM files. Sometimes the virus attempts to hide the extra files by either placing them into a different directory (but one on the PATH) or gives them a hidden attribute so a normal DIR command will not show them. And, of course, when the virus is active in memory it can effectively hide the COM files as well (but, unlike many viruses, a companion infector need not remain in memory to do its work).<\/p>\n<p>A good integrity map of what should be on the hard disk can be used to easily detect and clean companion viruses.<\/p>\n<p><strong>Note:<\/strong> There are some instances where it is normal to have both COM and EXE files of the same name (such as DOS 5&#8217;s DOSSHELL) but this is relatively rare. When this is the case, the companion virus will usually not change the existing COM file (although some are sloppy and will).<\/p>\n<p>Companion viruses were never particularly common and under Windows where specific files are associated with icons you likely won&#8217;t see them.<\/p>\n<h4>Summary<\/h4>\n<ul>\n<li>A companion virus installs a COM file (the virus) for every EXE file found on the disk.<\/li>\n<li>DOS runs COM files before EXE files and so the virus will run first, going into memory and then will execute the related EXE file.<\/li>\n<li>Companion viruses are relatively easy to find and eliminate if you have a good integrity map of what should be on your disk.<\/li>\n<\/ul>\n<table style=\"margin: 0pt; width: 100%;\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" align=\"center\">\n<tbody>\n<tr align=\"center\">\n<td style=\"padding: 0 0 0 0;\" colspan=\"2\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png\" alt=\"Up Arrow\" width=\"16\" height=\"16\" class=\"alignnone size-full wp-image-579\" \/> <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/what-viruses-infect.html\">What Viruses Infect<\/a> <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png\" alt=\"Up Arrow\" width=\"16\" height=\"16\" class=\"alignnone size-full wp-image-579\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 0 0 0 0;\" align=\"right\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/macros.html\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_prior.gif\" alt=\"Prior Page\" width=\"48\" height=\"32\" class=\"alignnone size-full wp-image-578\" \/><\/a><\/td>\n<td style=\"padding: 0 0 0 0;\" align=\"left\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/directories-cluster-viruses.html\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_next.gif\" alt=\"Next Page\" width=\"48\" height=\"32\" class=\"alignnone size-full wp-image-577\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-right: 20px; text-align: right; width: 50%;\"><a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/macros.html\">Macros<\/a> <\/td>\n<td style=\"padding-left: 20px; width: 50%; text-align: left;\"> <a href=\"https:\/\/www.cknow.com\/cms\/vtutor\/directories-cluster-viruses.html\">Directories (Cluster) Viruses<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Would you believe that a virus can infect your files without changing a single byte in the infected file? Well, it&#8217;s true; two different ways in fact! The more common of the two ways is called the companion or spawning virus (the other is a cluster virus). The companion virus infects your files by locating [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-795","post","type-post","status-publish","format-standard","hentry","category-vtutor","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Companion Files - C-Know Media<\/title>\n<meta name=\"description\" content=\"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Companion Files - C-Know Media\" \/>\n<meta property=\"og:description\" content=\"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html\" \/>\n<meta property=\"og:site_name\" content=\"C-Know Media\" \/>\n<meta property=\"article:published_time\" content=\"2013-02-28T23:57:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-04-16T20:23:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png\" \/>\n<meta name=\"author\" content=\"DaBoss\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"DaBoss\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html\"},\"author\":{\"name\":\"DaBoss\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\"},\"headline\":\"Companion Files\",\"datePublished\":\"2013-02-28T23:57:47+00:00\",\"dateModified\":\"2013-04-16T20:23:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html\"},\"wordCount\":502,\"image\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/arrow_up.png\",\"articleSection\":[\"VTutor\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html\",\"name\":\"Companion Files - C-Know Media\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/arrow_up.png\",\"datePublished\":\"2013-02-28T23:57:47+00:00\",\"dateModified\":\"2013-04-16T20:23:56+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\"},\"description\":\"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#primaryimage\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/arrow_up.png\",\"contentUrl\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/wp-content\\\/uploads\\\/2013\\\/02\\\/arrow_up.png\",\"width\":16,\"height\":16,\"caption\":\"Up Arrow\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/vtutor\\\/companion-files.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Companion Files\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#website\",\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/\",\"name\":\"C-Know Media\",\"description\":\"Fun media for all\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/#\\\/schema\\\/person\\\/47944007814fe46e32a1ebee5954638f\",\"name\":\"DaBoss\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g\",\"caption\":\"DaBoss\"},\"url\":\"https:\\\/\\\/www.cknow.com\\\/cms\\\/author\\\/daboss-2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Companion Files - C-Know Media","description":"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html","og_locale":"en_US","og_type":"article","og_title":"Companion Files - C-Know Media","og_description":"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.","og_url":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html","og_site_name":"C-Know Media","article_published_time":"2013-02-28T23:57:47+00:00","article_modified_time":"2013-04-16T20:23:56+00:00","og_image":[{"url":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png","type":"","width":"","height":""}],"author":"DaBoss","twitter_misc":{"Written by":"DaBoss","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#article","isPartOf":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html"},"author":{"name":"DaBoss","@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f"},"headline":"Companion Files","datePublished":"2013-02-28T23:57:47+00:00","dateModified":"2013-04-16T20:23:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html"},"wordCount":502,"image":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#primaryimage"},"thumbnailUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png","articleSection":["VTutor"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html","url":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html","name":"Companion Files - C-Know Media","isPartOf":{"@id":"https:\/\/www.cknow.com\/cms\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#primaryimage"},"image":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#primaryimage"},"thumbnailUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png","datePublished":"2013-02-28T23:57:47+00:00","dateModified":"2013-04-16T20:23:56+00:00","author":{"@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f"},"description":"Companion viruses make use of a DOS quirk that runs COM files before EXE files. The virus infects EXE files by installing a same-named COM file.","breadcrumb":{"@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#primaryimage","url":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png","contentUrl":"https:\/\/www.cknow.com\/cms\/wp-content\/uploads\/2013\/02\/arrow_up.png","width":16,"height":16,"caption":"Up Arrow"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cknow.com\/cms\/vtutor\/companion-files.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cknow.com\/cms\/"},{"@type":"ListItem","position":2,"name":"Companion Files"}]},{"@type":"WebSite","@id":"https:\/\/www.cknow.com\/cms\/#website","url":"https:\/\/www.cknow.com\/cms\/","name":"C-Know Media","description":"Fun media for all","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cknow.com\/cms\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.cknow.com\/cms\/#\/schema\/person\/47944007814fe46e32a1ebee5954638f","name":"DaBoss","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d4ba3f829b22682345f1dec9f43e839d822e1b4c570d7ce15475db8b4d5ce111?s=96&d=mm&r=g","caption":"DaBoss"},"url":"https:\/\/www.cknow.com\/cms\/author\/daboss-2"}]}},"_links":{"self":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts\/795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/comments?post=795"}],"version-history":[{"count":0,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/posts\/795\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/media?parent=795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/categories?post=795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cknow.com\/cms\/wp-json\/wp\/v2\/tags?post=795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}